10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Use<br />

UTF–8<br />

encoding<br />

<strong>for</strong><br />

tokens<br />

used<br />

in<br />

cross<br />

domain<br />

single<br />

sign-on.<br />

Beginning<br />

with<br />

Version<br />

5.1,<br />

<strong>WebSEAL</strong><br />

servers<br />

use<br />

UTF-8<br />

encoding<br />

by<br />

default.<br />

When<br />

this<br />

stanza<br />

entry<br />

is<br />

set<br />

to<br />

true,<br />

tokens<br />

can<br />

be<br />

exchanged<br />

with<br />

other<br />

<strong>WebSEAL</strong><br />

servers<br />

that<br />

use<br />

UTF-8<br />

encoding.<br />

This<br />

enables<br />

tokens<br />

to<br />

used<br />

across<br />

different<br />

code<br />

pages<br />

(such<br />

as<br />

<strong>for</strong><br />

a<br />

different<br />

language).<br />

For<br />

backwards<br />

compatibility<br />

with<br />

tokens<br />

created<br />

by<br />

<strong>WebSEAL</strong><br />

servers<br />

from<br />

version<br />

prior<br />

to<br />

5.1,<br />

set<br />

this<br />

stanza<br />

entry<br />

to<br />

false.<br />

This<br />

stanza<br />

entry<br />

is<br />

required.<br />

Default:<br />

true<br />

Example:<br />

use-utf8<br />

=<br />

true<br />

See<br />

also<br />

“Multi-locale<br />

support<br />

with<br />

UTF-8”<br />

on<br />

page<br />

44.<br />

[cdsso-peers]<br />

stanza<br />

fully_qualified_hostname<br />

=<br />

fully_qualified<br />

_path<br />

List<br />

of<br />

peer<br />

servers<br />

that<br />

are<br />

participating<br />

in<br />

cross-domain<br />

single-sign<br />

on.<br />

The<br />

path<br />

name<br />

must<br />

specify<br />

the<br />

location<br />

of<br />

server’s<br />

key<br />

file.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value<br />

Example:<br />

webhost2.ibm.com<br />

=<br />

/tmp/cdsso.key<br />

[cdsso-token-attributes]<br />

stanza<br />

domain_name<br />

=<br />

pattern1<br />

[pattern2,]<br />

[patternN,<br />

....<br />

]<br />

Credential<br />

attributes<br />

to<br />

include<br />

in<br />

CDSSO<br />

authentication<br />

tokens.<br />

The<br />

domain_name<br />

specifies<br />

the<br />

destination<br />

domain<br />

containing<br />

the<br />

server<br />

that<br />

will<br />

consume<br />

the<br />

token.<br />

The<br />

value<br />

<strong>for</strong><br />

domain_name<br />

can<br />

be<br />

one<br />

or<br />

more<br />

entries.<br />

The<br />

value<br />

can<br />

be<br />

either<br />

a<br />

specific<br />

value<br />

or<br />

can<br />

be<br />

a<br />

pattern<br />

that<br />

uses<br />

standard<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

wildcard<br />

characters<br />

(<br />

*,<br />

[],<br />

^,<br />

\,<br />

?).<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value<br />

Example:<br />

example1.com<br />

=<br />

my_cdas_attr_*<br />

<br />

=<br />

pattern1<br />

[pattern2,]<br />

[patternN,<br />

....<br />

]<br />

Credential<br />

attributes<br />

to<br />

include<br />

in<br />

CDSSO<br />

authentication<br />

tokens.<br />

When<br />

<strong>WebSEAL</strong><br />

cannot<br />

find<br />

a<br />

domain_name<br />

entry<br />

to<br />

match<br />

the<br />

domain,<br />

the<br />

entries<br />

in<br />

<br />

are<br />

used.<br />

The<br />

word<br />

<br />

is<br />

a<br />

key<br />

word<br />

and<br />

must<br />

not<br />

be<br />

modified.<br />

This<br />

stanza<br />

entry<br />

is<br />

optional.<br />

There<br />

is<br />

no<br />

default<br />

value<br />

Example:<br />

<br />

=<br />

my_cdas_attr_*<br />

[cdsso-incoming-attributes]<br />

stanza<br />

Appendix<br />

A.<br />

<strong>WebSEAL</strong><br />

configuration<br />

file<br />

reference<br />

429

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!